Privacy Policy
Last updated: 27 July 2026
1. Introduction
Threat Detective Ltd, formerly StoryIQ Ltd ("Company", "we", "us", or "our"), a company registered in England and Wales, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Threat Detective website at threatdetectivehq.com (the "Website").
Please read this Privacy Policy carefully. It is a notice explaining how we process personal data collected through the Website and the legal bases we rely on, set out in Section 4. Where we rely on your consent, for example for marketing emails, we ask for it separately and you can withdraw it at any time.
Note: This Privacy Policy covers the Website only. Data you provide in the Threat Detective application is governed by the application's own privacy policy at eu.threatdetectivehq.com/privacy.
2. Information We Collect
2.1 Information You Provide
We collect information that you voluntarily provide to us, including:
- Newsletter Information: Name and email address when you subscribe to our newsletter, The Detective’s Notebook
- Communication Data: Information you provide when you contact us for support or enquiries
2.2 Automatically Collected Information
When you visit the Website, we automatically collect certain information, including:
- Log Data: IP address, browser type, operating system, pages visited, time and date of visits
- Device Information: Device type, unique device identifiers
- Usage Data: How you interact with the Website, pages viewed, actions taken
2.3 Web Analytics
We use two analytics services to help us understand how visitors use our website:
Plausible Analytics is a privacy-friendly, cookieless analytics service. It collects anonymous usage data (page views, referral sources, country) without setting any cookies or collecting personal data. Plausible does not require consent under GDPR as it does not process personal data. Data is processed in the EU.
PostHog provides more detailed analytics and is only activated with your explicit consent via our cookie banner. When you consent, we collect page views, user interactions, session information, and technical data. PostHog data is processed in the EU. You can withdraw your consent at any time by clearing your browser cookies or by contacting us at privacy@threatdetectivehq.com.
2.4 Live Chat (Intercom)
We use Intercom to provide live chat support on our website. Before you accept cookies, Intercom operates in anonymous mode, allowing you to chat without setting tracking cookies. After you accept cookies, Intercom may set session cookies to improve your support experience and maintain conversation history.
Intercom may collect your name, email address, and conversation content if you choose to provide them during a chat session. This data is processed by Intercom, Inc. and is subject to their privacy policy. We use this data solely to respond to your enquiries and provide customer support.
2.5 Cookies
The cookies we use include:
- td_posthog_consent: Stores your cookie consent preference (expires after 1 year)
- ph_*_posthog: PostHog session and user identification cookies (only set with consent, expires after 1 year)
- intercom-*: Intercom session cookies (only set with consent in full mode)
Note: We do not use cookies for advertising or cross-site tracking. Plausible Analytics does not use cookies. PostHog and Intercom tracking cookies are only set with your explicit consent.
3. How We Use Your Information
We use the information we collect to:
- Operate and maintain the Website
- Send you newsletters and marketing communications (where you have opted in)
- Respond to your enquiries and provide support
- Monitor and analyse usage patterns to improve the Website
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations and enforce our Terms of Service
4. Legal Basis for Processing (UK GDPR)
Under UK GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide services you have requested through the Website
- Legitimate Interests: To improve the Website, ensure security, and conduct business operations
- Consent: For marketing communications and newsletters (which you can withdraw at any time)
- Legal Obligation: To comply with applicable laws and regulations
5. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
5.1 Service Providers
We may share your information with third-party service providers who perform services on our behalf, such as:
- Cloud hosting providers
- Email service providers (MailerLite for newsletters)
- Customer support platforms (Intercom for live chat)
- Web analytics providers (Plausible for cookieless analytics; PostHog for detailed analytics with your consent)
These service providers are contractually obligated to protect your information and use it only for the purposes we specify.
5.2 Legal Requirements
We may disclose your information if required by law or in response to valid legal requests, such as:
- Court orders or legal processes
- Requests from law enforcement or regulatory authorities
- Protection of our legal rights and interests
- Prevention of fraud or security threats
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
6. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Newsletter subscriber email addresses are retained while you remain subscribed. When you unsubscribe or request removal, we remove your details from our active mailing list and keep only a minimal suppression record (your email address) so that we do not email you again. We review retained personal data at least annually and delete records that are no longer needed.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, misuse, or alteration. These measures include:
- Encryption of data in transit and at rest
- Regular security assessments and monitoring
- Access controls and authentication mechanisms
- Staff training on data protection
However, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security.
8. International Data Transfers
Where possible, our service providers process personal data in the UK or EU. If we transfer your personal information outside the UK or EU, we will ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the UK Information Commissioner's Office
- Adequacy decisions recognising equivalent data protection standards
- Other legally approved transfer mechanisms
9. Your Rights Under UK GDPR
You have the following rights regarding your personal information:
- Right of Access: Request a copy of your personal information
- Right to Rectification: Request correction of inaccurate or incomplete information
- Right to Erasure: Request deletion of your personal information (subject to legal obligations)
- Right to Restrict Processing: Request limitation on how we use your information
- Right to Data Portability: Receive your information in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or for marketing purposes
- Right to Withdraw Consent: Withdraw consent for processing where consent was the legal basis
To exercise these rights, please contact us using the details in Section 13. We will respond to your request within one month.
10. Marketing Communications
If you have opted in to receive marketing communications or subscribed to our newsletter (The Detective’s Notebook), we will send you emails about:
- Product updates and new features
- Cybersecurity regulatory insights and guides (The Detective’s Notebook newsletter)
- Industry news and resources
- Special offers and promotions
You can unsubscribe from marketing emails at any time by clicking the "unsubscribe" link in any email or by contacting us directly.
11. Third-Party Links
The Website may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:
- Posting the updated Privacy Policy on our website
- Updating the "Last updated" date at the top of this page
- Sending you an email notification (for significant changes)
Your continued use of the Website after changes indicates your acceptance of the updated Privacy Policy.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:
Threat Detective Ltd
Company Number: 07273811
2a The Quadrant
Epsom, Surrey
KT17 4RH
United Kingdom
Email: privacy@threatdetectivehq.com
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you believe we have not handled your personal information appropriately. Visit ico.org.uk for more information.